GHSA-5r2g-59px-3q9w

Suggest an improvement
Source
https://github.com/advisories/GHSA-5r2g-59px-3q9w
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-5r2g-59px-3q9w/GHSA-5r2g-59px-3q9w.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5r2g-59px-3q9w
Aliases
Published
2024-11-15T12:31:45Z
Modified
2024-11-19T20:26:50Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Stored XSS using two files in usememos/memos
Details

A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a malicious script and reference it in an HTML file. When the HTML file is accessed, the malicious script is executed. This can lead to the theft of sensitive information, such as login credentials, from users visiting the affected website. The issue has been fixed in version 0.10.0.

Database specific
{
    "nvd_published_at": "2024-11-15T11:15:08Z",
    "cwe_ids": [
        "CWE-79"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-11-15T21:00:28Z"
}
References

Affected packages

Go / github.com/usememos/memos

Package

Name
github.com/usememos/memos
View open source insights on deps.dev
Purl
pkg:golang/github.com/usememos/memos

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.10.0